A vulnerability described as problematic has been identified in ellite Wallos up to 4.9.5. The affected element is the function ZipArchive::extractTo of the file /endpoints/db/restore.php of the component Zip Extraction. The manipulation results in path traversal. This vulnerability was named CVE-2026-61639. The attack may be performed from remote. There is no available exploit. Upgrading the af
PHP
Vulnerability
CVE-2026-61639
VulDB
Apply vendor security patch